whenever you find the worst pits of the internet, you will find cloudflare there, quietly making money off it.
Notices by Foone🏳️⚧️ (foone@digipres.club), page 4
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:22 JST Foone🏳️⚧️
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:21 JST Foone🏳️⚧️
it also refuses to run if your external IP is one of a couple, which include a hungarian ISP, a couple IPs in moscow, and azure
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:20 JST Foone🏳️⚧️
it is also apparently dumping these stolen passwords into a discord somewhere, and if it steals your wallet password it dumps it with "🤡 Leet Stealer"
even the bad guys think you're a clown for using cryptocurrency
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:10 JST Foone🏳️⚧️
on a day with no ADHD meds, my roommate knocks on the door and is like "a friend got their discord hacked but before I knew it they sent me an EXE and I ran it. am I hacked?"
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:09 JST Foone🏳️⚧️
seems it is an electron based javascript malware that tries to steal all your passwords from all your browsers
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:09 JST Foone🏳️⚧️
I am some kind of reverse engineer/security engineer but I'm not very good at it WHEN MY BRAIN DOESN'T WORK
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:08 JST Foone🏳️⚧️
huh, one of the things it does is check your RAM speed.
I think because that's a thing real computers have, and it's trying to do a roundabout VM check?
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:07 JST Foone🏳️⚧️
it even checks against OllyDbg, a really great debugger that hasn't updated in 11 years
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:07 JST Foone🏳️⚧️
but yeah it does a bunch of checks to see if anything remotely debuggy or VMy is running or even installed, then refuses to do stuff
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:06 JST Foone🏳️⚧️
I'm looking at this disassembly from dez_ on twitter.
https://gist.github.com/joe-desimone/64b3c1044c184ffc8f26090d7bcd32b5
-
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:05 JST Foone🏳️⚧️
yes let me accidentally try to unpack the electron app in poland, that's exactly the kind of protection I need: geographic protection
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:05 JST Foone🏳️⚧️
there's a lot of very specific checks before it tries to do anything, I think this has been carefully designed to appear innocuous to the commonly used online sandboxes. like, it detects if it's running on virustotal and throws an error, instead of doing anything sneaky-deaky
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:04 JST Foone🏳️⚧️
god I bet there are some malware out there that checks your location on GPS before running, and errors out if you're too close to Known Antivirus companies
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:03 JST Foone🏳️⚧️
OH GOOD this is a different version that uses aes compression. so the source isn't just obfuscated, it's actually encrypted.
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:03 JST Foone🏳️⚧️
sure there's work-from-home, but you're probably still within a reasonable driving distance of the office. they could just blacklist the entire metropolitan area
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:02 JST Foone🏳️⚧️
I hope these fuckers aren't trying to obfuscate the password by abusing javascript scoping
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:01 JST Foone🏳️⚧️
finally unencrypted and re-deobfuscated.
and it's got debugging strings in Turkish!
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:01 JST Foone🏳️⚧️
my head already hurts enough as it is
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:57:00 JST Foone🏳️⚧️
awfully lot of debugging information printed to console.log by this malware. it really tells you everything it is doing
In conversation from digipres.club permalink -
Embed this notice
Foone🏳️⚧️ (foone@digipres.club)'s status on Friday, 28-Mar-2025 06:56:59 JST Foone🏳️⚧️
so it also checks your GPU.
You know, because VMs usually have a GPU like "VMware SVGA 3D"
In conversation from digipres.club permalink